Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 240

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Anthropic limits Mythos AI rollout over fears hackers could use model for cyberattacks
Levi Strauss revenue jumps again, with DTC making up more than half of sales for the first time
Tell me about barre classes
Countries around the world are considering teen social media bans – why experts warn it’s a ‘lazy’ fix
Australians charged with war crimes?
Two-gender musical duos?
Movie: Half Lives
Queer for Fear: The History of Queer Horror: Queer for Fear: The History of Queer Horror
Monarch: Legacy of Monsters: Requiem
Robinhood’s Trump Accounts partnership signals big upside for the stock, analysts say